ZeroHour

CVE-2019-7860

CVSS 3.0
7.5 high
EPSS
1%p66
Published
()
Modified
Description

A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

Vendors
magento
Products
magento
Ecosystems
E-commerce
Weakness
CWE-338
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.